WP Clinic
Log in Sign up

CVE · Critical

CVE-2025-13773 — Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13773 Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0 Improper Control of Generation of Code ('Code Injection') Critical 9.8 < 5.9.0 5.9.0 2025-12-23

CVE-2025-13773

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Delivery_Notes::update' function. This is due to missing capability check in the 'WooCommerce_Delivery_Notes::update' function, PHP enabled in Dompdf, and missing escape in the 'template.php' file. This makes it possible for unauthenticated attackers to execute code on the server.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.